PT-2026-22399 · Unknown · Http::Session2
Publicado
2026-02-27
·
Atualizado
2026-03-08
·
CVE-2018-25160
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HTTP::Session2 versions through 1.09
Description
The software does not properly validate user-provided session IDs, which could allow for code injection or other impacts depending on the session backend. For example, if memcached is used for session storage, an attacker might be able to inject memcached commands within the session ID value.
Recommendations
Update to a version of HTTP::Session2 greater than 1.09.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Http::Session2